Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 122/324
6.3
CVE-2025-3589

A vulnerability, which was classified as critical, was found in SourceCodester Music Class Enrollment System 1.0. Affect

6.3
CVE-2025-3676

A vulnerability classified as critical has been found in xxyopen Novel-Plus 3.5.0. This affects an unknown part of the f

6.3
CVE-2025-3684

A vulnerability was found in Xianqi Kindergarten Management System 2.0 Bulid 20190808. It has been rated as critical. Th

6.3
CVE-2025-3685

A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. Affected is

6.3
CVE-2025-3696

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Thi

6.3
CVE-2025-3697

A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Managemen

6.3
CVE-2025-3796

A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unk

6.3
CVE-2025-3817

A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue

6.3
CVE-2025-3818

A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._

6.3
CVE-2025-3856

A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function sea

6.3
CVE-2025-3955

A vulnerability, which was classified as critical, was found in codeprojects Patient Record Management System 1.0. This

6.3
CVE-2025-3956

A vulnerability has been found in 201206030 novel-cloud 1.4.0 and classified as critical. This vulnerability affects the

6.3
CVE-2025-3957

A vulnerability was found in opplus springboot-admin 1.0 and classified as critical. This issue affects some unknown pro

6.3
CVE-2025-3968

A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been declared as critical. This vul

6.3
CVE-2025-4021

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Thi

6.3
CVE-2025-4072

A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This issue affects so

6.3
CVE-2025-4080

A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. Affected by this

6.3
CVE-2025-4109

A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by th

6.3
CVE-2025-4110

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this is

6.3
CVE-2025-4111

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been classified as critical. This affec

6.3
CVE-2025-4113

A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been rated as critical. This issue a

6.3
CVE-2025-4154

A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. Affect

6.3
CVE-2025-4155

A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unkn

6.3
CVE-2025-4156

A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affe

6.3
CVE-2025-4157

A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. This issue affects some unkn

6.3
CVE-2025-4163

A vulnerability, which was classified as critical, has been found in PHPGurukul Land Record System 1.0. This issue affec

6.3
CVE-2025-4173

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerabili

6.3
CVE-2025-4196

A vulnerability was found in SourceCodester Patient Record Management System 1.0. It has been rated as critical. This is

6.3
CVE-2025-4197

A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. Affected is

6.3
CVE-2025-4243

A vulnerability, which was classified as critical, has been found in code-projects Online Bus Reservation System 1.0. Af

6.3
CVE-2025-4244

A vulnerability, which was classified as critical, was found in code-projects Online Bus Reservation System 1.0. This af

6.3
CVE-2025-4247

A vulnerability, which was classified as critical, was found in SourceCodester Simple To-Do List System 1.0. Affected is

6.3
CVE-2025-4248

A vulnerability has been found in SourceCodester Simple To-Do List System 1.0 and classified as critical. Affected by th

6.3
CVE-2025-4352

A vulnerability, which was classified as critical, has been found in Brilliance Golden Link Secondary System up to 20250

6.3
CVE-2025-4353

A vulnerability, which was classified as critical, was found in Brilliance Golden Link Secondary System up to 20250424.

6.3
CVE-2025-4458

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. Affec

6.3
CVE-2025-4459

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected

6.3
CVE-2025-4510

A vulnerability was found in Changjietong UFIDA CRM 1.0. It has been declared as critical. This vulnerability affects un

6.3
CVE-2025-4514

A vulnerability, which was classified as critical, has been found in Zhengzhou Jiuhua Electronic Technology mayicms up t

6.3
CVE-2025-4541

A vulnerability classified as critical has been found in LmxCMS 1.41. Affected is the function manageZt of the file c\ad

6.3
CVE-2025-4695

A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical.

6.3
CVE-2025-4696

A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been declared as critical. Af

6.3
CVE-2025-4743

A vulnerability classified as critical was found in code-projects Employee Record System 1.0. Affected by this vulnerabi

6.3
CVE-2025-4770

A vulnerability, which was classified as critical, has been found in PHPGurukul Park Ticketing Management System 2.0. Th

6.3
CVE-2025-4777

A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This a

6.3
CVE-2025-4778

A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been declared as critical. This vul

6.3
CVE-2025-4780

A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been rated as critical. This issue

6.3
CVE-2025-4781

A vulnerability classified as critical has been found in PHPGurukul Park Ticketing Management System 2.0. Affected is an

6.3
CVE-2025-4782

A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This

6.3
CVE-2025-4786

A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0. It has been rated as critical. This i

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started